Information Disclosure Vulnerability in Microsoft Excel by Microsoft
CVE-2019-1446
5.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 12 November 2019
Summary
An information disclosure vulnerability exists in Microsoft Excel that allows for the improper disclosure of memory contents, potentially leading to sensitive data exposure. This flaw can be exploited by attackers to gain access to confidential information that should remain protected within the application. It emphasizes the need for users to apply the latest security patches and maintain vigilance against potential exploits.
Affected Version(s)
Excel Services on Microsoft SharePoint Server 2010 Service Pack 2 = unspecified
Microsoft Excel 2010 Service Pack 2 (32-bit editions)
Microsoft Excel 2010 Service Pack 2 (64-bit editions)
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved